HAZY_TIGER__2019__Suspected_BITTER_APT_Continues_Targeting_Government_of_China_and_Chinese_Organizations_Anomali.pdf
ID: ce10e7f6-419f-4183-bb9e-c4e216344376
STIX ID: report--ce10e7f6-419f-4183-bb9e-c4e216344376
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2019-08-09
Last Modified Date: 2019-08-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Anomali researchers identified an active phishing campaign, attributed to the suspected "BITTER APT", targeting Chinese government agencies and state-owned organisations by deploying spoofed webmail login pages (using Let's Encrypt DV certificates) to harvest credentials; the report enumerates multiple malicious domains, hosting providers and IPs, provides screenshots and indicators of compromise, and assesses the campaign as likely espionage-motivated.
